Threat Intel
43% of all websites run WordPress — making it the #1 attack surface worldwide 1 in 25 WordPress sites is actively infected with malware right now 97% of CMS-based attacks specifically target WordPress plugins & themes 50,000+ vulnerabilities indexed · WPScan threat database 71% of hacked WordPress sites had a backdoor silently installed 4,000+ plugins carry known, unpatched security vulnerabilities Average breach goes undetected for 197 days — is your site clean? Outdated plugins are responsible for 52% of all WordPress infections SQL injection & XSS remain the top two WordPress attack vectors 60% of infections exploit a vulnerability that already had a patch available 43% of all websites run WordPress — making it the #1 attack surface worldwide 1 in 25 WordPress sites is actively infected with malware right now 97% of CMS-based attacks specifically target WordPress plugins & themes 50,000+ vulnerabilities indexed · WPScan threat database 71% of hacked WordPress sites had a backdoor silently installed 4,000+ plugins carry known, unpatched security vulnerabilities Average breach goes undetected for 197 days — is your site clean? Outdated plugins are responsible for 52% of all WordPress infections SQL injection & XSS remain the top two WordPress attack vectors 60% of infections exploit a vulnerability that already had a patch available
Scan Free →
wp-scan.org

What's New

Changelog

Improvements, fixes and new features

v2.4
May 2026
New
  • Added Razorpay payment gateway for India (Card, UPI, NetBanking, EMI)
  • Razorpay webhook for payment safety net — license issued even if browser closes
  • Large Scan Credits — scan ZIPs up to 500 MB with pay-per-scan credits
  • Admin Reports tab — monthly revenue & subscriber reports with PDF export
  • Auto-send monthly email report on 1st of each month
  • File integrity monitoring — detect unauthorised changes to core files
  • Login rate limiting — 5 attempts then 15-min lockout
  • Audit log — all admin actions logged with IP and timestamp
  • Session fingerprint hardening against hijacking
v2.3
April 2026
Improvement
  • Admin pagination and filters for Users, Payments, Licenses, Coupons tabs
  • Admin Reports tab with 12-month revenue history
  • Premium badge moved to top of hero, redesigned stats section
  • Large file upload restriction with Contact Support button
  • Removed Server Path tab (security hardening)
v2.2
March 2026
Improvement
  • Affiliates system with commission tracking
  • Coupon codes with percentage discounts and expiry
  • PayPal subscription support (monthly recurring)
  • License auto-renew tracking with subscr_id
  • Geo-detection: INR pricing for India, USD for international
v2.1
February 2026
Fix
  • Scan result HTML export for Premium users
  • Dashboard scan history
  • Improved malware detection patterns (40+ rules)
  • CSRF protection on all forms
  • XSS hardening across all templates
v2.0
January 2026
New
  • Full rewrite with Premium tier (Monthly / Yearly / Lifetime)
  • License key system with expiry and auto-renewal
  • User dashboard with license management
  • Stripe and PayPal payment integration
  • Admin panel with user, payment, and license management
v1.0
December 2025
New
  • Initial public launch
  • Free WordPress security scanner — upload ZIP, get report in under 10 seconds
  • 20+ detection patterns: malware, SQLi, XSS, file inclusion, obfuscated code